Skip to main content

      The EU’s Critical Entities Resilience Directive (CER) aims to strengthen the resilience of essential services across key sectors, including energy, transport, banking and financial market infrastructures, health, drinking water, wastewater, digital infrastructure, public administration, and space. CER replaces and modernizes earlier critical infrastructure rules, shifting the focus from asset protection to service continuity and organizational resilience.

      In practice, CER requires competent authorities to identify critical entities and for those entities to implement proportionate resilience measures across risk management, physical and cyber-physical security, supply chain dependencies, incident handling, and continuity planning. It also establishes supervision and enforcement mechanisms at Member State level and fosters cross-border cooperation.

      Introducing your quarterly update on CER

      Welcome to our concise article series designed for operational resilience leaders, risk owners, and board stakeholders. Each update will highlight:

      • Regulatory milestones and what they mean in practice.
      • Implementation priorities and good practices
      • Key dates and events to support your program.
      • Practical tools and insights from our CER specialists

      Regulatory status update

      The EU Directive has been transposed into Belgian Law in January 2026. The main sectors in scope are energy, transport, banking, financial market infrastructures, digital infrastructures, drinking water, wastewater, health, public administrations, space, production, processing and distribution of food.

      By 17 July, organizations identified as in-scope should have received confirmation from the relevant competent authority. If you believe your organization may be in scope but have not received a notification, we recommend:

      • Engaging with your national competent authority for clarity on status and timing.
      • Reviewing your sector’s classification and essential service dependencies.
      • Preparing baseline evidence of resilience measures in anticipation of supervisory engagement.

      What this means for you: Confirmed in-scope entities should now be prioritizing gap assessments against CER requirements, establishing governance (roles, accountability, and reporting), and planning remediation roadmaps across people, processes, and technology.

      What to focus on next

      Once notified, CER requirements must be translated into concrete governance, risk assessment, resilience planning, and incident notification capabilities. The obligations follow a sequence: assign accountability, assess all-hazard risks, define resilience measures, and prepare for timely notification.

      a.     Mandatory 24/7 contact point: single interface to all authorities.

      b.     Personnel security screening on request by sectoral authority.

      c.      Documentation obligation: E.R.P., risk assessment, inventories, exercise records, incident reports.

      d.     Available for inspection at all times.

      a.     All-hazards scope: natural, man-made, public health, hybrid/terrorism threats.

      b.     Include cross-sector and cross-border dependencies (utilities, suppliers, logistics, digital).

      c.      Input: sectoral risk assessment.

      a.     Technical, security, and organizational measures (proportionate to risk).

      b.     Prevention, such as disaster risk reduction and climate adaptation.

      c.      Physical protection, such as fences, barriers, access controls, and monitoring.

      d.     Emergency response, crisis procedures, business continuity, and alternate supply chains.

      a.     Notify sectoral authority and national contact point.

      b.     Deadline: as soon as possible, max 24 hours after significant disruption.

      c.      Significance criteria: users affected, duration, and geographical area.

      d.     Content: nature, cause, consequences, and cross-border implications.

      How we can help

      Olivier Elst

      Partner | Advisory

      KPMG in Belgium

      Gap/readiness assessment

      • Gap assessment vs. articles (risk assessment, resilience measures, incident reporting, supply/dependency mapping, and testing).

      CER controls framework

      • Set up of a risk-controls framework for CER to ensure implementation and enforce continuity.

      Roadmap to implementation

      • Translation of the gaps into recommendations. Quick wins and detailed roadmap are developed.

      CER implementation

      • End‑to‑end CER program setup: governance, policy set, risk/treat taxonomy, KRIs/KPIs, and reporting templates to competent authorities.
      • Criticality and dependency mapping: services, assets, ICT and non‑ICT suppliers, and cross‑border dependencies.
      • Exercising and testing: crisis simulations, stress tests, and lessons‑learned cycles.

      Managed resilience monitoring

      • Managed resilience monitoring: threat watch, obligation tracking, and control assurance.
      • Training and education pathways: ops teams, suppliers, and board.


      Upcoming event

      Join our ‘CER: From Directive to Practice’ event on 15 September for a practical walkthrough of the CER Directive and the latest developments:



      Spotlight on CER

      In the meantime, you can stay informed via our articles on CER:

      An in-depth analysis of the new Critical Entities Resilience Directive and its impact on your organization.

      Strengthening the resilience of critical services across Europe

      Read here our Dutch and French version of our 'Enhancing infrastructure resilience across Europe' article.


      Stay Connected

      To subscribe to our quarterly newsletter on CER, submit topics you want covered, or request a briefing, please contact:


      Explore

      Enterprise risk & assurance

      Risk & regulatory services.
      Advisory risk

      Stay informed

      Be the first to know about top business trends that can drive success for your company.

      stay informed